← D-TRUST cases
Bugzilla #1390990 Certificate Misissuance Delayed Revocation

D-TRUST non-BR-compliant certificate issuance and delayed revocation/remediation

RESOLVED FIXED D-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns D-TRUST certificates that Mozilla identified as not compliant with Baseline Requirements, including a certificate with a dNSName containing '/' and certificates with short or sequential-looking serial numbers. Mozilla opened the bug after problems were reported in mozilla.dev.security.policy and asked D-TRUST to stop issuance, identify affected certificates, explain the cause, and provide a remediation and revocation plan. D-TRUST said it had stopped the problematic issuance, revoked the dNSName certificate, and later worked through revocation of the short-serial-number certificates in phases. The thread also records D-TRUST’s explanations for the issuance issues, including a CSR validator bug, UI/usability issues, and a delayed serial-number migration across platforms. For the short-serial-number issue, D-TRUST eventually reported that all affected certificates were revoked by 2018-07-16, and Mozilla later said the issue was resolved. For the dNSName issue, D-TRUST reported the certificate was revoked and a replacement BR-compliant certificate was issued.

Model: gpt-5.4-mini Generated: 2026-06-13 17:04 UTC Revised: 2026-06-16 18:28 UTC Confidence: 0.97 39 comments
Chronology
  1. D-TRUST stopped issuing certificates with the dNSName '/' problem
  2. The dNSName-containing certificate was revoked
  3. D-TRUST reported a final incident report and revocation plan for the affected certificates
  4. D-TRUST reported that all short-serial-number certificates were revoked
  5. Mozilla said the issue was resolved
Thread Activity
  1. Mozilla representative — Mozilla opened the bug and requested details on awareness, issuance stoppage, affected certificates, root cause, remediation steps, and revocation timing.
  2. D-Trust — D-TRUST said it learned of the CN/SAN issue from mozilla.dev.security.policy and the serial-number issue from an internal audit, and it described initial remediation steps and timelines.
  3. D-Trust — D-TRUST explained the GUI usability issue and CSR validator bug, and said it had extended software testing and vendor/customer change processes.
  4. D-Trust — D-TRUST provided a revised timeline, said the dNSName certificate was revoked, and said it would finalize revocation of affected serial-number certificates by 2017-09-15.
  5. Bdr representative — D-TRUST filed final reports for both incidents, stating the dNSName certificate was revoked and that the short-serial-number issue involved phased replacement and revocation.
  6. Bdr representative — D-TRUST reported that all certificates with short serial numbers were revoked in three phases.
  7. Bdr representative — D-TRUST said the remaining revocations were completed by 2018-07-16, that 150 certificates were published to CT logs, and that 111 had no customer approval for publication.
  8. Fastly representative — Mozilla stated that the response had been informative and that the issue was resolved.
Participants
Mozilla representative D-Trust Community commenter Bdr representative Fastly representative Titanous representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1599561 RESOLVED Certificate Misissuance Opened 2019-11-26 · Closed 2023-02-22 · 100% similar
D-TRUST: EV certificates with incorrectly used businessCategory entry
#1463975 RESOLVED Certificate Misissuance Delayed Revocation Opened 2018-05-24 · Closed 2023-02-22 · 96% similar
GRCA: Misissued certificates: Invalid commonName, commonName not in SAN
#1075952 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2014-10-01 · Closed 2022-11-14 · 95% similar
D-Trust: issuing 1024 bit certificates
#1390988 RESOLVED Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 91% similar
Consorci AOC: Non-BR-Compliant Certificate Issuance
#1390977 RESOLVED Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 91% similar
Camerfirma: Non-BR-Compliant Certificate Issuance
#1391058 RESOLVED Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 89% similar
PROCERT: Non-BR-Compliant Certificate Issuance
#2023458 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-03-15 · Closed 2026-06-12 · 89% similar
D-Trust: TLS Precertificates Exceeding the Maximum Validity Period Allowed by the TLS Baseline Requirements
#1391429 RESOLVED Certificate Misissuance Revocation Issue Opened 2017-08-17 · Closed 2024-02-27 · 86% similar
GoDaddy: Non-BR-Compliant Certificate Issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action